Kimsuky, known as a hacking group under North Korea's Reconnaissance General Bureau, was found to have set up a local large language model (LLM) and a retrieval-augmented generation (RAG) environment to use Generative AI throughout its attack process.
Cybersecurity corporations Genians said on the 10th that its analysis of Kimsuky's recent attack activity found signs that the group has been accumulating research and technical validation to use Generative AI-based tools in its attack framework.
Until now, North Korean hacking groups have mainly used spearphishing emails that impersonate actual work contacts and target diplomacy and security experts. A representative method is that when the recipient runs a malicious shortcut file disguised as a document inside a compressed file attached to the email, a PowerShell script runs in the background.
However, Genians said this analysis found traces that go beyond simply using AI to create lures, showing that the threat actor directly built a local LLM runtime and a RAG environment and operated an AI-based development environment.
Specifically, indications were identified that tools such as Ollama, GPT4All, and Msty for running and managing local LLMs, RAG environments, AI agent development frameworks, and speech-to-text (STT) tools were built or used. Multiple traces of installing and using Cursor, an AI coding tool, were also found.
Genians said this is interpreted as an attempt to analyze exfiltrated documents and to automate information extraction and attack tasks by using local LLMs that can operate without sending data to external services.
The lure documents used in attacks also appear to be getting more sophisticated. Previously, it was mainly confirmed that stolen legitimate documents were being reused, but recently, documents related to virtual assets and finance that are presumed to have been created with Generative AI were used in spearphishing.
In particular, the virtual asset sector was a primary target, with malicious documents disguised as investment strategy reports and financial materials being continuously distributed. During the analysis, indications were also identified that the actors attempted to check for exposure of personal information such as virtual asset wallet details, Gmail account information, and website signup histories.
Moon Jong-hyun, head of the Genians Security Center (GSC), said, "This analysis shows that a nation-backed hacking group is advancing its attack capabilities by building local LLMs and AI development environments to integrate AI into actual attack frameworks," adding, "As social engineering attacks are expected to become more sophisticated with advances in AI technology, an EDR-based threat-hunting framework that focuses on execution behavior rather than document content is more important than anything else."
The analysis results are being shared through domestic and international cooperation channels, including the Korea Internet & Security Agency (KISA) Threat Intelligence Network Council. The full report is available on the Genians website.